CVE-2024-56736

Severity
6.5MEDIUM
EPSS
0.2%
top 54.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16

Description

Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Apache HertzBeat: Server-Side Request Forgery (SSRF) in Api Config Oss2025-04-16
GHSA
GHSA-gj7g-7f7f-wjr5: Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat2025-04-16
CVE-2024-56736 (MEDIUM CVSS 6.5) | Server-Side Request Forgery (SSRF) | cvebase.io